Skip to content

API accepts requests without a valid token when authentication is enabled and role-based authorization is disabled - #5982

Merged
ramonsmits merged 1 commit into
release-6.21from
backport-ff995c9-to-6.21
Oct 9, 2026
Merged

ramonsmits merged 1 commit into
release-6.21from
backport-ff995c9-to-6.21

Conversation

@ramonsmits

@ramonsmits ramonsmits commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

…disabled (#5979)

PermissionPolicyProvider chose between the role-checking policy and an
allow-all policy by looking only at
Authentication.RoleBasedAuthorizationEnabled. With authentication enabled
and RBAC at its default of false, every permission resolved to allow-all.
Every controller action carries a permission policy, so the
RequireAuthenticatedUser fallback policy never applied. Requests without a
token, or with an invalid or expired token, reached the controllers on the
error, audit and monitoring instances.

The provider now uses both settings:

- Authentication disabled: allow-all. RBAC is ignored.
- Authentication enabled, RBAC disabled: every permission requires an
  authenticated user. This is the behavior from before role-based access
  control was added.
- Authentication and RBAC enabled: unchanged.

Other changes:

- The startup log line for the authentication settings includes the RBAC
  setting.
- The monitoring container health check calls the anonymous root endpoint
  instead of /connection. /connection requires an authenticated user when
  authentication is enabled.

Tests:

- Unit tests evaluate every permission through the real registrations, for
  each combination of the two settings.
- New When_authentication_is_enabled_without_role_based_authorization
  acceptance fixtures on all three instances. When RBAC was added, the
  existing fixtures were switched to RBAC enabled only, which removed the
  coverage for the default configuration.
  - A request without a token to every route that is not [AllowAnonymous]
    gets 401. This test fails without the fix.
  - A valid token without roles is accepted.
- The existing When_authentication_is_enabled fixtures (RBAC enabled) also
  run the every-route test.

Co-authored-by: Dennis van der Stelt <dvdstelt@gmail.com>
(cherry picked from commit ff995c9)
@ramonsmits
ramonsmits merged commit f89817d into release-6.21 Oct 9, 2026
36 checks passed
@ramonsmits
ramonsmits deleted the backport-ff995c9-to-6.21 branch October 9, 2026 14:24
@ramonsmits ramonsmits changed the title Require authentication on permission policies when role-based authorization is disabled API accepts requests without a valid token when authentication is enabled and role-based authorization is disabled Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants